Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

rundeck — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting rundeck. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Rundeck serves as an IT automation platform for workflow orchestration and task management, enabling organizations to streamline operational processes. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from improper input validation and access control weaknesses. While no major public security incidents have been widely documented, the platform's 9 recorded CVEs highlight potential risks in authentication mechanisms and plugin integrations. Security teams should implement strict input sanitization, principle of least privilege configurations, and regular dependency updates to mitigate these risks. The platform's extensibility through plugins introduces additional attack surfaces requiring careful vetting of third-party components.

Top products by rundeck: rundeck
CVE ID Title CVSS Severity Published
CVE-2026-106056 Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting — rundeck CWE-78 7.5 High 2026-10-07
CVE-2026-105834 Rundeck before 6.2.0 Arbitrary File Read via File Resource Model Source — rundeck CWE-22 6.5 Medium 2026-10-06
CVE-2026-92763 Rundeck through 6.2.1 Authorization Bypass via Project Import — rundeck CWE-862 8.1 High 2026-09-16
CVE-2023-47112 Authenticated users can view job names and groups they do not have authorization to view in Rundeck — rundeck CWE-862 4.3 Medium 2023-11-16
CVE-2023-48222 Authenticated users can view or delete jobs they do not have authorization for in Rundeck — rundeck CWE-862 8.1 High 2023-11-16
CVE-2022-31044 Plaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process Automation — rundeck CWE-256 7.5 High 2022-06-15
CVE-2022-29186 Use of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterprise — rundeck CWE-321 9.1 Critical 2022-05-20
CVE-2021-41112 Missing Authorization in Rundeck — rundeck CWE-862 8.1 High 2022-02-28
CVE-2021-41111 Authorization Bypass Through User-Controlled Key in Rundeck — rundeck CWE-639 6.4 Medium 2022-02-28
CVE-2021-39133 Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck server — rundeck CWE-352 7.2 High 2021-08-30
CVE-2021-39132 YAML deserialization can run untrusted code — rundeck CWE-502 8.8 High 2021-08-30
CVE-2020-11009 IDOR can reveal execution data and logs to unauthorized user in Rundeck — rundeck CWE-200 6.5 Medium 2020-04-29

This page lists every published CVE security advisory associated with rundeck. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.